Vulnerability in HT Mega Addons for Elementor – Elementor Widgets & Template Builder — CVE-2026-11895
MediumSeverity
0.2%Estimated exploit probability
70,000+ sitesInstalls
3.1.2Fixed in
What to do now
Update HT Mega Addons for Elementor – Elementor Widgets & Template Builder to 3.1.2 or later.
Affected versions
- Everything up to and including 3.1.1
Affected: HT Mega Addons for Elementor – Elementor Widgets & Template Builder (plugin, ht-mega-for-elementor)
What the vulnerability is
The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.